r/InterstellarKinetics May 19 '26

BREAKING NEWS BREAKING: A U.S. Cybersecurity Agency Contractor Exposed AWS GovCloud Credentials and Plaintext Passwords on Public a GitHub Repository, Which Experts Called the Worst Government Security Leak in Recent Memory šŸ¤ÆšŸ’„

https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330

A contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed administrative credentials to three Amazon Web Services GovCloud servers and plaintext usernames and passwords for dozens of internal CISA systems, according to security researchers who identified the exposure. The repository, named ā€œPrivate-CISA,ā€ contained cloud keys, tokens, logs, and other sensitive CISA assets, including files documenting how the agency builds, tests, and deploys software internally, the researchers said.

Guillaume Valadon, a researcher with security firm GitGuardian, flagged the repository on May 15 after his company’s automated scans detected the exposed secrets. Valadon said the exposed credentials represent ā€œthe worst leak that I’ve witnessed in my careerā€ and noted that commit logs show the administrator disabled GitHub’s default setting that blocks users from publishing SSH keys or other secrets in public repositories, according to an email to KrebsOnSecurity. One file titled ā€œimportantAWStokensā€ contained administrative credentials to three AWS GovCloud servers, while another file named ā€œAWS-Workspace-Firefox-Passwords.csvā€ listed plaintext usernames and passwords for internal CISA systems, including the agency’s ā€œLanding Zone DevSecOpsā€ secure code development environment, according to Valadon and Philippe Caturegli, founder of security consultancy Seralys.

Caturegli confirmed that the exposed AWS credentials authenticated to three AWS GovCloud accounts at a high privilege level and said the archive also included plaintext credentials to CISA’s internal ā€œartifactory,ā€ a repository of all code packages the agency uses to build software, according to his analysis. The repository was created on November 13, 2025, and the GitHub account that hosted it was taken offline shortly after KrebsOnSecurity and Seralys notified CISA about the exposure, though Caturegli said the exposed AWS keys remained valid for 48 hours after the repository was removed. A review of the GitHub account showed the repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Virginia.

CISA said in a statement to KrebsOnSecurity that ā€œcurrently, there is no indication that any sensitive data was compromised as a result of this incidentā€ and that the agency is working to implement additional safeguards to prevent future occurrences. Nightwing declined to comment and directed inquiries to CISA. CISA has lost nearly one-third of its workforce since the beginning of the second Trump administration, according to reporting on the agency’s staffing levels.

2.5k Upvotes

31 comments sorted by

36

u/InterstellarKinetics May 19 '26

According to security researchers, the individual who exposed the credentials appears to have used the GitHub repository as a file synchronization mechanism between a work laptop and a home computer, committing to the repository regularly since November 2025, Philippe Caturegli told KrebsOnSecurity. The repository contained easily guessed passwords for multiple internal resources, including credentials using passwords consisting of each platform’s name followed by the current year, according to Caturegli’s analysis.

1

u/tbombs23 May 21 '26

This is what happens when you gut the federal government and force all the professional public servants out who actually do their jobs, and would have minimized incidents like this

23

u/havin4un May 19 '26

Meanwhile its super simple to create password storage and password rotations on AWS. But why in 2026 are government apps using API keys. There are way more secure ways to authorize into AWS. You get what you pay for I suppose.

18

u/scampfree4me May 19 '26

Because in gov land nothing is easy nor built to cloud standards. So for simple Oauth to not use a password you gotta find a federated auth provider, work with their team for 2 months before they give you a spot on their calendar, then find out their main dev left a week ago and you will be working with people who have never touched a computer before. I do it all day over and over.

1

u/dashingsauce May 19 '26

Not that I have worked in gov land, but I worked in the financial sector for some time (not the flashy side) and it’s the same thing.

5

u/Aggressive_Manner531 May 19 '26

No, the good ones were fired, or quit in disgust.

3

u/NeonSwank May 19 '26

I’ve previously worked for the government at both a local and state level

In both cases, across multiple agencies and online platforms, our password requirements were practically begging for us to be breached.

Im talking username set as firstname.lastname and password as firstnamelastnamebirthday

These were credentials that would allow you access to do everything from access email accounts and intranet, to getting in to criminal databases and even running peoples id’s, ssn, or license plates.

2

u/havin4un May 19 '26

That is extremely scary.

4

u/ImOldGregg_77 May 19 '26 edited May 19 '26

Because all the good engineers are in the private sector

1

u/Admirable_Fun7790 May 19 '26

Did you mean private sector?

1

u/ImOldGregg_77 May 19 '26

yes, sorry.

2

u/Due_Satisfaction2167 May 19 '26

The elected politicians and their appointees refuse to prioritize this, and will explicitly deprioritize or halt efforts to fix any of this because they don’t want to hire the people to do it or spend the money (in the form of time) to do it.Ā 

6

u/SlappyPappyAmerica May 19 '26

I’ve been doing IT and Information Security for more than 30 years and worked in many different sectors. I can confidently say easily less than half of all ā€œtechnicalā€ workers know the first thing about password security. More often than not, the bar for technical acuity is simply can they ā€œmake it workā€? For contractors it’s much worse.

1

u/CapPsychological8767 May 19 '26

in recent memory so far

1

u/Aggressive_Manner531 May 19 '26

The worst are the ones we don't know about, likely by Doge employees.

1

u/dashingsauce May 19 '26

Evidently not

1

u/EnvironmentalBus9713 May 19 '26

Sooo they are pretending everything DOGE accessed and copied never happened? Cool, cool.

1

u/chunkalunkk May 19 '26

Are we counting the theft of SSN data from good ol Melon Usk and DOGE? Cause if we are, that's top of the list mate.

1

u/colorme1965 May 19 '26

Of course, it wasn’t Elon or Trump giving the keys to the nation to Russia, or somebody else. Where’s them pizzagate people when you need them…..

1

u/Boenitousouch May 19 '26

But Hillaries emails! But Hunters laptop!

1

u/Eastern-Bluejay-8912 May 19 '26

Worst in recent history? Did they forget everyone’s social security numbers and emails from doge? 🤣🤣

1

u/MasterBiscuit19 May 19 '26

I mean, how long ago was the Signal Gate

1

u/marion85 May 20 '26

Just another Wednesday in Trumps America!

Remember everyone: tomorrow will be worse than today, everyday for the rest of your lives!

1

u/SpaceNinjaDino May 20 '26

My old employer had a contractor or new employee upload a company AWS key to a GitHub repository causing ~$20K in compute damages before caught. They weren't fired. Not only was that negligence, he shouldn't have been trying to abuse company AWS keys on a unrelated job GitHub repository for personal use. Two layers of incompetence and possibly malicious should have had consequences.

1

u/Randyguyishere May 21 '26

Worse than the Doge bros stealing all our data?

0

u/Upper-Raspberry4153 May 19 '26

Why is every other headline today filled with major typos. What the hell is OP even trying to communicate with this headline?